This report is auto-generated from the latest RBAC Atlas scan (2026-05-04). It analyzes the RBAC permissions of 257 Kubernetes open-source projects across 25972 manifest versions to provide a snapshot of the current cloud-native threat landscape.

At a Glance

MetricValue
Projects analyzed257
Total manifest versions25972
Avg service accounts per project2.11
Avg permission bindings per project30.62
Avg workloads per project3.51
Avg critical risks per project3.53
Avg high risks per project3.5
Avg medium risks per project2.24
Avg low risks per project21.36
Projects with critical risks171
Projects with no RBAC permissions54

Risk Distribution

Risk LevelCountPercentage
Critical90611.51%
High89911.42%
Medium5757.31%
Low548969.75%
Total7869

Top 10 RBAC Risk Tags

Risk TagOccurrences
InformationDisclosure1116
WildcardPermission938
Tampering863
ClusterWideAccess761
PotentialPrivilegeEscalation593
Reconnaissance535
DataExposure527
PrivilegeEscalation452
ResourceNameRestricted395
DenialOfService329

Top 10 Triggered Risk Rules

RuleOccurrences
Base Risk Level - Low6931
Base Risk Level - High758
Read ConfigMaps in a namespace257
Read secrets in a namespace237
Read secrets cluster-wide189
Base Risk Level - Medium177
Read ConfigMaps cluster-wide163
Modify ConfigMaps in a namespace158
List Namespaces (Cluster Reconnaissance)146
Read RBAC configuration cluster-wide142

Top 10 Riskiest Projects

Ranked by weighted risk score (critical×10 + high×5 + medium×2 + low×1), using only the latest version of each project.

ProjectVersionCriticalHighMediumLowScore
openebs3.9.09073301701495
victoria-metrics-distributed0.9.013117539764
longhorn1.9.2205637493
gitlab9.9.318109199447
eg-universal-agent-operator0.0.51624864360
gitlab-operator2.9.22067115359
kuadrant-operator1.4.2219494357
flux22.9.21830024354
victoria-metrics-k8s-stack0.9.81317598323
opentelemetry-kube-stack0.9.413913111312

Top 10 Projects by Permission Count

ProjectPermissions
openebs363
gitlab236
rook-ceph185
stackgres-operator181
victoria-metrics-distributed174
tigera-operator167
gateway-operator162
gitlab-operator148
opentelemetry-kube-stack146
edp-install142